arrow
返回

Poisoned source code detection in code models

delete2025-03-01
delete0
delete
OA
AI
E
Ehab Ghannoum *
M
Mohammad Ghafari
DOI:10.1016/j.jss.2025.112384delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Deep learning models have gained popularity for conducting various tasks involving source code. However, their black-box nature raises concerns about potential risks. One such risk is a poisoning attack, where an attacker intentionally contaminates the training set with malicious samples to mislead the model's predictions in specific scenarios. To protect source code models from poisoning attacks, we introduce CodeGarrison (CG), a hybrid deep-learning model that relies on code embeddings to identify poisoned code samples. We evaluated CG against the state-of-the-art technique ONION for detecting poisoned samples generated by DAMP, MHM, ALERT, as well as a novel poisoning technique named CodeFooler. Results showed that CG significantly outperformed ONION with an accuracy of 93.5%. We also tested CG's robustness against unknown attacks, achieving an average accuracy of 85.6% in identifying poisoned samples across the four attacks mentioned above.
Keyword:
Poisoned code detection
Source code poisoning
Adversarial machine learning

期刊

Journal of Systems and Software 封面图
Journal of Systems and Software
IF:
4.1
论文数:
5.4K
被引数:
8.4K

机构

T
tu clausthal
学者数:
1.8K
论文数: 1.7K
被引数: 14
引用论文

引用论文

暂无论文信息